GLSA 201909-05: WebkitGTK+: Multiple vulnerabilities
Severity: | normal |
Title: | WebkitGTK+: Multiple vulnerabilities |
Date: | 09/06/2019 |
Bugs: |
|
ID: | 201909-05 |
Synopsis
Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.Background
WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
net-libs/webkit-gtk | < 2.24.4 | >= 2.24.4 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in WebkitGTK+. Please review the CVE identifiers referenced below for details.
Impact
An attacker, by enticing a user to visit maliciously crafted web content, may be able to execute arbitrary code or cause memory corruption.
Workaround
There is no known workaround at this time.
Resolution
All WebkitGTK+ users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.24.4"
References
WSA-2019-0004 WSA-2019-0002 CVE-2019-8690 CVE-2019-8690 CVE-2019-8689 CVE-2019-8689 CVE-2019-8688 CVE-2019-8688 CVE-2019-8687 CVE-2019-8687 CVE-2019-8686 CVE-2019-8686 CVE-2019-8684 CVE-2019-8684 CVE-2019-8683 CVE-2019-8683 CVE-2019-8681 CVE-2019-8681 CVE-2019-8680 CVE-2019-8680 CVE-2019-8679 CVE-2019-8679 CVE-2019-8678 CVE-2019-8678 CVE-2019-8677 CVE-2019-8677 CVE-2019-8676 CVE-2019-8676 CVE-2019-8673 CVE-2019-8673 CVE-2019-8672 CVE-2019-8672 CVE-2019-8671 CVE-2019-8671 CVE-2019-8669 CVE-2019-8669 CVE-2019-8666 CVE-2019-8666 CVE-2019-8658 CVE-2019-8658 CVE-2019-8649 CVE-2019-8649 CVE-2019-8644 CVE-2019-8644 CVE-2019-8615 CVE-2019-8607 CVE-2019-8595 CVE-2019-8563 CVE-2019-8559 CVE-2019-8558 CVE-2019-8551 CVE-2019-8544 CVE-2019-8536 CVE-2019-8535 CVE-2019-8524 CVE-2019-8523 CVE-2019-8518 CVE-2019-8515 CVE-2019-8506 CVE-2019-8503 CVE-2019-7292 CVE-2019-7285 CVE-2019-6251 CVE-2019-6201 CVE-2019-11070
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.